SECURE BOOT // ISGD
ACCESS GRANTED
CLICK OR PRESS ANY KEY TO SKIP
Information Security · Offensive Security · Banking

Md. Zahid
Hossain

Senior information security professional safeguarding financial infrastructure — spanning penetration testing, threat intelligence, and ISO 27001 governance.

Senior Executive Officer, Information Security & Governance Division — Private Commercial Bank, Dhaka.

15+
Years in IT & Security
5.5+
Years in Banking
11
Professional Certs
#1
Fin. Inst. — Nat. Cyber Drill
Portrait of Md. Zahid Hossain
SECURITY LEAD Dhaka · BD
01 Profile

Defending the systems that move money.

I lead vulnerability assessment, penetration testing, and security governance inside a commercial bank, where a missed finding is measured in real customer trust. My work spans the full assessment lifecycle — scoping, exploitation, remediation tracking, and audit-ready reporting — across mobile, API, infrastructure, and cloud.

Across 15+ years in IT and security, I've moved from network engineering into offensive security and ISMS governance, mapping findings against the standards that regulators actually check: Bangladesh Bank ICT Security Guideline, ISO/IEC 27001, PCI DSS, SWIFT CSP, and OWASP.

I hold the EC-Council offensive track end to end — CEH, ECSA, and LPT Master — alongside threat intelligence and ISO 27001 Lead Auditor credentials, and I've represented my institution to a national #1 placement among financial institutions in the Bangladesh Cyber Drill.

Core Focus Areas

VAPT Penetration Testing Threat Intelligence Mobile App Security API Security Cloud Security Malware Analysis ISO 27001 PCI DSS SWIFT CSP PAM Risk Management Security Awareness OWASP
02 Credential Registry

Verified certifications.

Every credential below is independently verifiable through its issuing body and credential ID.

ENTRIES: 11
ISSUERS: ISC2 · EC-Council · Mile2 · BV · Microsoft · Cisco · Qualys · OPSWAT
Idx
Credential
Issuer
ID / Reference
001
LPT MasterLicensed Penetration Tester (Master)
EC-Council
ECC0694523871 · 2021
002
ECSA v10EC-Council Certified Security Analyst
EC-Council
ECC8142039675 · 2021
003
CEHCertified Ethical Hacker · score 91.2
EC-Council
ECC8519360742 · 2020
004
C)TIACertified Threat Intelligence Analyst
Mile2
17554-168-997-3713 · 2023
005
CCCertified in Cybersecurity
ISC2
1237127 · 2023
006
ISO/IEC 27001 Lead AuditorISMS · CQI & IRCA certified course
Bureau Veritas
22/IN/1023466/2670 · 2022
007
Adv. Malware Analysis & Ransomware40-hour certified expert course
CyberFoxTrain
CFT/CN000221903018 · 2022
008
Qualys Certified SpecialistVulnerability Mgmt · Scanning Strategies
Qualys
VM · SS · 2020
009
OCFA & ICIPCybersecurity Fundamentals · Critical Infrastructure
OPSWAT
o5QjNoeidw · 2024
010
MCSE / MCSA / MCPServer Infrastructure · Windows Server 2012
Microsoft
E251-0753 · 2013
011
CCNACisco Certified Network Associate
Cisco
CSCO11527615 · 2008
03 Certifications

The credentials, in full.

Every certificate below is genuine and verifiable. Filter by category, or open any card to view the full certificate.

04 Experience

A path from networks to offensive security.

JUL 2019 — PRESENT
Senior Executive Officer
Mercantile Bank PLC Information Security & Governance

Lead VAPT, penetration testing, and threat analysis across the bank's digital platforms. Develop threat & vulnerability management policies, drive ISO 27001 and PCI DSS programs as project manager, and run institution-wide security awareness. Primary point of contact for investigating and resolving security incidents.

SEP 2013 — MAR 2017
Network Administrator
BIPSOT Bangladesh Army & UN

Built and secured intranet/internet networks for a UN peace-support training institute. Managed Active Directory, Linux web/e-learning servers, MikroTik core routing with load balancing, and the CPTM online examination platform for the Bangladesh Army, Navy, and Air Force.

NOV 2010 — JUN 2013
System Engineer
Incepta Pharmaceuticals Ltd. IT — Head Office

Maintained domain controllers, mail and SMS servers, and inter-site data links between head office and manufacturing plants. Managed Kaspersky AV, proxy, VPN, and MikroTik bandwidth control, with full server backup and uptime monitoring.

DEC 2006 — FEB 2010
Support Engineer — NMC
Link3 Technologies Ltd. Network Monitoring Center

Monitored base-station systems and resolved faults across client networks. Configured and troubleshot switches, routers, and radio links, and delivered networking projects for enterprise clients.

05 Recognition

Awards & competition results.

2023

ICT Minister Award — MIST LeetCon

Rank 10 nationally across Bangladesh and 1st among all financial institutions in the national cybersecurity contest.

2022

National Cyber Drill — 1st (Fin. Institutions)

Led team MBL_XForce to first place among financial institutions, organized by BGD e-GOV CIRT (N-CERT).

2021

National Cyber Drill — 1st (Fin. Institutions)

First place among financial institutions for the second consecutive year with team MBL_XForce.

2022

Best Performer — Cyber Drill Programs

Recognized by the Managing Director & CEO of Mercantile Bank for outstanding results in Financial and National Cyber Drill programs.

2021

Presidium Award — Magna Cum Laude

Silver Medal for academic distinction in the M.Sc. in Computer Science program.

2023

ACS Skills Assessment — Australia

Assessed suitable for skilled migration under ANZSCO 263111 (Computer Network & Systems Engineer) by the Australian Computer Society.

06 Education

Academic background.

M.Sc. in Computer Science
American International University — Bangladesh
CGPA 3.88 / 4.002021
Praesidium Award · Magna Cum Laude · Silver Medal
B.Sc. in Computer Science
American International University — Bangladesh
CGPA 3.07 / 4.002006
Foundation in computer science & networking
Open to international & remote security roles

Let's secure something.

Available for penetration testing, security assessment, and information security advisory engagements — locally in Dhaka and internationally.